Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-45405

больше 3 лет назад

Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-45404

больше 3 лет назад

Through a series of popup and <code>window.print()</code> calls, an at ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-45404

больше 3 лет назад

Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-45403

больше 3 лет назад

Service Workers should not be able to infer information about opaque c ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-45403

больше 3 лет назад

Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-42932

больше 3 лет назад

Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported m ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-42932

больше 3 лет назад

Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-42931

больше 3 лет назад

Logins saved by Firefox should be managed by the Password Manager comp ...

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2022-42931

больше 3 лет назад

Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2022-42930

больше 3 лет назад

If two Workers were simultaneously initializing their CacheStorage, a ...

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-45405

Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45404

Through a series of popup and <code>window.print()</code> calls, an at ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45404

Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45403

Service Workers should not be able to infer information about opaque c ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45403

Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-42932

Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported m ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-42932

Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-42931

Logins saved by Firefox should be managed by the Password Manager comp ...

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-42931

Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-42930

If two Workers were simultaneously initializing their CacheStorage, a ...

CVSS3: 7.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться